Security Architecture Strategy: Develop, maintain, and communicate the domain-specific security architecture vision, strategy, and roadmap, ensuring alignment with WPP’s overall enterprise security strategy and business goals.
Secure Design & Development: Provide expert architectural guidance and oversight for key projects and initiatives within the domain, advocating for secure design principles, patterns, and practices throughout the software development lifecycle.
Compliance & Governance: Ensure that architectural designs and implementations adhere to relevant regulatory compliance frameworks (e.g., GDPR, CCPA, ISO 27001) and internal security policies. Participate in security audits and assessments, translating findings into actionable architectural improvements.
Threat & Risk Management: Conduct architectural risk assessments and threat modelling within the domain, identifying potential vulnerabilities and recommending appropriate mitigating controls. Integrate risk management practices into architectural decision-making.
Cybersecurity Integration: Embed advanced cybersecurity concepts, technologies, and best practices (e.g., identity and access management, data protection, network security, incident response capabilities) into the domain’s architecture.
Standards & Patterns: Define and promote security architecture standards, guidelines, and reusable patterns for the domain to foster consistency, efficiency, and robustness across solutions. Create associated designs and artefacts as the requirement arises.
Stakeholder Collaboration: Work closely with other Enterprise Architects, Security Operations, CISO office, Development Teams, Product Owners, and Legal/Compliance to translate security requirements into technical solutions and gain consensus on solutions and architectural direction.
Technology Evaluation: Research, evaluate, and recommend new security technologies and architectural approaches that can enhance the security posture and efficiency of the domain.
Documentation & Communication: Create clear, concise, and comprehensive security architecture documentation, including diagrams, principles, and decision records. Effectively communicate complex security concepts to technical and non-technical audiences.
Security Solution Architecture: When required, form, lead and contribute to successful deliver of specific security solutions and workstreams.